vendor:
WebfolioCMS
by:
Ivano Binetti
7.5
CVSS
HIGH
CSRF
352
CWE
Product Name: WebfolioCMS
Affected Version From: 1.1.2004
Affected Version To: 1.1.2004
Patch Exists: NO
Related CWE:
CPE:
Platforms Tested: Debian Squeeze (6.0)
2012
WebfolioCMS <= 1.1.4 CSRF (Add Admin/Modify Pages)
WebfolioCMS 1.1.4 (and lower) is affected by a CSRF Vulnerability which allows an attacker to add a new administrator, modify web pages, and change other WebfolioCMS parameters. The exploit demonstrates how to add an administrator account and modify existing and published web pages.
Mitigation:
Implement CSRF protection mechanisms, such as using tokens and validating referrer headers.